Tools AI Risk Radar ai-incident-0076
Incident record
Goose recipe security scan misses executable extension and retry fields
- Severity
- High
- Status
- Proof-of-concept
- Type
- Agent Hijack
- Target
- goose recipes
- Actor
- researcher
- CVE
- CVE-2026-85623
What happened
The CVE published on 4 September records command execution through shared recipes, whose stdio extension commands and retry checks bypass the recipe security scan. The record lists versions through 1.49.0 as affected and assigns CVSS 3.1 8.8. The researcher’s public issue dates to July; this entry dates the CVE publication. Review executable fields before running a shared recipe. The cited issue remains open at the 10 September check.
Sources
- CVE record and affected versionscveawg.mitre.org/api/cve/CVE-2026-85623
- Researcher report in the goose repositorygithub.com/aaif-goose/goose/issues/10325
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026